Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 5 Topic 1 Discussion

Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 5 Topic 1 Discussion

SCS-C02 Exam Topic 1 Question 5 Discussion:
Question #: 5
Topic #: 1

A company has two AWS accounts: Account A and Account B. Account A has an IAM role that IAM users in Account B assume when they need to upload sensitive documents to Amazon S3 buckets in Account A.

A new requirement mandates that users can assume the role only if they are authenticated with multi-factor authentication (MFA). A security engineer must recommend a solution that meets this requirement with minimum risk and effort.

Which solution should the security engineer recommend?


A.

Add an aws:MultiFactorAuthPresent condition to therole's permissions policy.


B.

Add an aws:MultiFactorAuthPresent condition to therole's trust policy.


C.

Add an aws:MultiFactorAuthPresent condition to thesession policy.


D.

Add an aws:MultiFactorAuthPresent condition to theS3 bucket policies.


Get Premium SCS-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.